Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall rule on Secondary dissappeared when enable firewall rule sync in HA

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 3 Posters 510 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bowbth
      last edited by

      Hi All,

      I'm a pfsense newbie.
      I have two routers that run esxi and install pfSense on it, both pfsense have the same version and configurations. I want to try HA to sync firewall rules from master to slave. So, I've following this guildeline https://vorkbaard.nl/how-to-set-up-pfsense-high-availability-hardware-redundancy/.

      However, when I had selected option 'firewall rule' in Select option to sync then master firewall automatically deleted firewall rule in SYNC interface on slave.

      How can I solve this ?

      Here is a rule of SYNC interface on slave before deleted by master
      0_1540542752095_sync.png

      after that it not be able to sync anymore until I deselect firewall rule sync option and recreate a new rule on sync.

      for the others sync option, it's working fine except firewall rule. Tested by randomly create a fake rule, the values from master already on slave.

      for another problem is,
      0_1540543428499_error_pfsense.png

      Why it keeps showing this error ? once I choose mark all as read, the new pop-up showing same as this.

      Thank you in advanced.

      1 Reply Last reply Reply Quote 0
      • nodauN
        nodau
        last edited by

        pls read this before.

        Norman

        virtualized pfSense 2.7.2 HA-Cluster on vsphere 8

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          You need a rule like that on the secondary for the initial sync. When that sync happens the rule on the sync interface on the Primary will sync to that interface so it also needs to be in place.

          If the rule is on the sync interface on the primary and you end up with nothing on the sync interface on the secondary you likely have an interface mismatch.

          Use Status > Interfaces on both to be sure they match. Everything on every interface has to match exactly

          Example:
          WAN Interface (wan, igb0)
          LAN Interface (lan, igb1.223)
          MGMT Interface (opt1, igb1.999)

          All three elements must match (WAN, wan, igb0) (MGMT, opt1, igb1.999) in the same order.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.